PT-2024-24598 · Tolgee · Tolgee

Jan Cizmar

·

Published

2024-04-18

·

Updated

2024-04-18

·

CVE-2024-32470

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tolgee versions 3.57.2 through 3.57.3
Description Tolgee is an open-source localization platform. When an API key created by an admin user is used, it bypasses the permission check at all.
Recommendations For Tolgee versions 3.57.2 through 3.57.3, update to version 3.57.4 to resolve the issue. As a temporary workaround, consider restricting the use of API keys created by admin users until the update is applied.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-32470
GHSA-PM57-HCM8-38GW
GHSA-R95P-FQQV-FPPC

Affected Products

Tolgee